Fenetres qui s'ouvrent seules ..

Bonjour,
J'ai un problème de vpages qui souvraient seules sur mon ordinateur.. Problemes de connection a msn j'ai donc effectué un scan avg anti spyware et je vous joins mon log Hi Jack This :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:31, on 2008-02-26
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fnhotmail%2fhelp%2f%3f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A5532934-90B8-446E-BCB8-29DE08F9089B} - C:\Program Files\Windows NT\cydiqowej777444.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: 0 - {DA0B482C-DAAA-4029-E1BA-72DCFA014906} - C:\Program Files\Movie Maker\rybivoked.dll (file missing)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [niwor] C:\Program Files\Windows NT\niwor77798.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [NoDNS] C:\Program Files\\NoDNS\\NoDNS.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'Default user')
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
O23 - Service: perfmons Service (perfmons) - Unknown owner - C:\Windows\system32\perfs.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Routing Service (Routing) - Unknown owner - C:\Windows\system32\routing.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

--
End of file - 8748 bytes
Configuration: Windows Vista
Internet Explorer 7.0

25 réponses

Résumé de la discussion

Une infection malveillante est décrite, entraînant des pages qui s’ouvrent seules et des soucis de connexion vers MSN, après un scan AVG Anti-Spyware et un log HijackThis. Les éléments importants de réponse incluent l’exécution d’un nettoyage en mode sûr via Malekal_morte, la suppression de clés et fichiers suspects, et la vérification avec des outils comme ComboFix et OTMoveIt. Des logs montrent des suppressions et des déplacements de composants dans Windows et les répertoires, puis une promesse de rescan et de désinfection complète à venir. Les éléments détectés concernent des noms de programmes et services parfois indétectables initialement, rendant nécessaire une vérification approfondie et un suivi du nettoyage pour prévenir toute réinfection.

Bobot (l’IA à votre service)
  1. Salut,

    Pour commencer :

    Désactiver le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    ---> Démarrer
    ---> Panneau de configuration
    --->
    Double Clique sur l'icône "Comptes d'utilisateurs"
    --->
    Clique ensuite sur désactiver
    ---> Valider


    _____________________________________________________

    Mets JAVA à jour :
    https://www.java.com/fr/download/manual.jsp
    ---------------------------------------------------------------------
    Tester Java et autres players:
    TesT-1
    TesT-2

    _____________________________________________________

    Ensuite fait tous le reste bien dans l'ordre.

    On arrête le service puis on le désactive :
    _____________________________________________________

    Arrête ces services

    service(s) à arrêter : Routing Service - Planificateur LiveUpdate automatique - perfmons Service

    pour ça fais cette manip :

    - Clique Droit sur "Ordinateur" sur le bureau
    - Gérer
    - Services et Applications
    - Services
    - Clic droit sur le service cité -
    - propriétés
    - et dans "type de démarrage" et mets le sur « désactivé ».
    - Ensuite si le "Status du service" est sur "Démarré" faire : « arrêté »

    _____________________________________________________

    OTMoveIt :

    Télécharger sur le bureau :
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

    = Copier le texte en gras:

    C:\Windows\system32\perfs.exe
    C:\Windows\system32\routing.exe
    C:\Program Files\Windows NT\niwor77798.exe
    C:\Program Files\Windows NT\cydiqowej777444.dll


    = Double-clic sur OTMoveIt.exe
    = Dans le cadre de Gauche ==> clic-droit ==> coller
    = Clic MoveIt!
    = si redémarrage demandé==> Clic : YES
    = Un rapport dans ==> C:\_OTMoveIt\MovedFiles\date du jour à copier/coller sur le forum.
    -------

    redemarre le PC

    _____________________________________________________

    Fixe les lignes dans Hijackthis :

    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/

    O2 - BHO: (no name) - {A5532934-90B8-446E-BCB8-29DE08F9089B} - C:\Program Files\Windows NT\cydiqowej777444.dll
    O2 - BHO: 0 - {DA0B482C-DAAA-4029-E1BA-72DCFA014906} - C:\Program Files\Movie Maker\rybivoked.dll (file missing)

    O4 - HKLM\..\Run: [niwor] C:\Program Files\Windows NT\niwor77798.exe

    S'il te demande un redémarrage, relance ton PC.
    _____________________________________________________

    Clean.zip

    Télécharge sur ton bureau : http://www.malekal.com/download/clean.zip

    Une fois sur le bureau, tu fais un clic droit sur ton fichier clean.zip et dans le menu déroulant, tu clics sur extrait tout ou extraire ici.
    Cela va créer un dossier clean.
    Double-clic sur ce dossier clean, tu y trouveras dedans plusieurs fichiers.
    Double-clic sur clean. Cela va ouvrir une fenêtre noire.
    Un menu va apparaître, choisis l'option 1 en appuyant sur la touche 1 de ton clavier.
    Clean va travailler. (ça peut etre un peu long)
    Un rapport va etre généré, colle le contenu entier ici.
    « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum. )

    _____________________________________________________
    0
    1. Si c'est sur msn que tes pages s'ouvrent toutes seules, alors t'as le virus qui fait fureur en ce moment, que bientot tout le monde l'aura ...

      http://www.msncreative.net/index.php/Dernieres_news/Supprimer_le_virus_msn-photos.isuisse.com_circulant_sur_Messenger_/id_menu_69.html

      va voir ici, tout est expliké, mais c'est surbooké ...
      0
      1. Salut,

        Dans son HijackThis, il y'a d'autres infections :)
        0
    2. Merci beaucoup !
      Je procede a la desinfection et rescannerai !
      Merci beaucoup
      0
      1. Log MOve It
        C:\Windows\system32\perfs.exe moved successfully.
        C:\Windows\system32\routing.exe moved successfully.
        File/Folder C:\Program Files\Windows NT\niwor77798.exe not found.
        DllUnregisterServer procedure not found in C:\Program Files\Windows NT\cydiqowej777444.dll
        C:\Program Files\Windows NT\cydiqowej777444.dll NOT unregistered.
        C:\Program Files\Windows NT\cydiqowej777444.dll moved successfully.

        OTMoveIt2 v1.0.20 log created on 02262008_230542
        0
        1. Trés bien, Fixe bien les lignes dans HjT puis poste le rapport de clean.
          0
          1. Rapport Clean

            2008-02-26 a 23:11:21.47

            *** Recherche C:

            *** Recherche C:\Windows\

            *** Recherche C:\Windows\system32
            C:\Windows\system32\wininit.exe FOUND
            C:\Windows\system32\wininit.exe FOUND

            *** Recherche C:\Program Files
            "C:\Program Files\InetGet2\" FOUND
            "C:\Program Files\Viewpoint\" FOUND
            0
            1. Re

              Démarre en mode sans échec :

              Pour démarrer en mode sans échec :

              1/ -Démarrez Windows, ou s’il s’exécute, fermez Windows puis éteignez l'ordinateur.
              2/ -Redémarrez l’ordinateur.
              3/ -Au début du chargement du BIOS (mais pas trop tôt), commencez à appuyer sur la touche F8 de votre clavier plusieurs fois de suite. Procédez ainsi jusqu'à ce que le menu des options avancées de Windows apparaissent.
              4/ -En utilisant les flèches de votre clavier, sélectionnez "Mode sans échec" dans le menu puis appuyez sur Entrée.

              Une fois dans windows :

              - Double-clic sur clean.cmd
              - Une fenêtre va apparaître, choisis l'option 2, suis les consignes et poste le rapport clean

              _____________________________________________________

              Navilog1 :

              Télécharger et Install Navilog1 sur le bureau :
              http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

              = double-clic dessus pour l'installer et le lancer
              Quand installé
              = taper F
              = Appuyer sur une touche jusqu' arriver aux options
              = Choisir option 1 ( = taper 1 )
              ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

              un rapport : fixnavi.txt
              dans ==> C :
              le copier/coller dans la réponse

              _____________________________________________________

              Repost un log HijackThis.
              0
              1. cript executed in Safe Mode
                Rapport clean par Malekal_morte - http://www.malekal.com
                Script executed in Safe Mode 2008-02-26 a 23:30:21.72

                Microsoft Windows [version 6.0.6000]

                *** Suppression C:

                *** Suppression C:\Windows\

                *** Suppression C:\Windows\system32
                tentative de suppression de C:\Windows\system32\wininit.exe
                Impossible de supprimer C:\Windows\system32\wininit.exe
                tentative de suppression de C:\Windows\system32\wininit.exe
                Impossible de supprimer C:\Windows\system32\wininit.exe

                *** Suppression C:\Program Files
                tentative de suppression de "C:\Program Files\InetGet2\"
                tentative de suppression de "C:\Program Files\Viewpoint\"

                *** Deletion of the registry keys successful..

                La suite arrive !
                0
                1. Search Navipromo version 3.4.2 commencé le 2008-02-26 à 23:34:38.55

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Postez ce rapport sur le forum pour le faire analyser !!!
                  !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                  Outil exécuté depuis C:\Program Files\navilog1
                  Mise à jour le 21.01.2008 à 14h00 par IL-MAFIOSO

                  Microsoft Windows Vista 6.0.6000
                  Internet Explorer : 7.0.6000.16609
                  Système de fichiers : NTFS

                  Executé en mode sans échec

                  *** Recherche Programmes installés ***

                  *** Recherche dossiers dans C:\Windows ***

                  *** Recherche dossiers dans C:\Program Files ***

                  *** Recherche dossiers dans C:\ProgramData ***

                  *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

                  *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs ***

                  *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Local\virtualstore\Program Files ***

                  *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Roaming ***

                  *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                  pour + d'infos : http://www.gmer.net

                  Aucun Fichier trouvé

                  *** Recherche avec GenericNaviSearch ***
                  !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                  !!! A vérifier impérativement avant toute suppression manuelle !!!

                  * Recherche dans C:\Windows\system32 *

                  * Recherche dans C:\Users\Lexxcoop\AppData\Local\Microsoft *

                  * Recherche dans C:\Users\Lexxcoop\AppData\Local\virtualstore\windows\system32 *

                  * Recherche dans C:\Users\Lexxcoop\AppData\Local *

                  *** Recherche fichiers ***

                  *** Recherche clés spécifiques dans le Registre ***

                  *** Module de Recherche complémentaire ***
                  (Recherche fichiers spécifiques)

                  1)Recherche nouveaux fichiers Instant Access :

                  2)Recherche Heuristique :

                  * Dans C:\Windows\system32 :

                  * Dans C:\Users\Lexxcoop\AppData\Local\Microsoft :

                  * Dans C:\Users\Lexxcoop\AppData\Local\virtualstore\windows\system32 :

                  * Dans C:\Users\Lexxcoop\AppData\Local :

                  3)Recherche Certificats :

                  Certificat Egroup absent !

                  4)Recherche fichiers connus :

                  *** Analyse terminée le 2008-02-26 à 23:48:23.32 ***

                  Log Navilog

                  Ici Le HJT

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 23:49, on 2008-02-26
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                  Boot mode: Safe mode with network support

                  Running processes:
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Windows\notepad.exe
                  C:\Windows\system32\NOTEPAD.EXE
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fnhotmail%2fhelp%2f%3f
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                  O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'SYSTEM')
                  O4 - HKUS\S-1-5-18\..\Run: [NoDNS] C:\Program Files\\NoDNS\\NoDNS.exe (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'Default user')
                  O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O13 - Gopher Prefix:
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                  O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
                  O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                  O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
                  O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
                  O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                  0
                  1. Search Navipromo version 3.4.2 commencé le 2008-02-26 à 23:34:38.55

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Postez ce rapport sur le forum pour le faire analyser !!!
                    !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                    Outil exécuté depuis C:\Program Files\navilog1
                    Mise à jour le 21.01.2008 à 14h00 par IL-MAFIOSO

                    Microsoft Windows Vista 6.0.6000
                    Internet Explorer : 7.0.6000.16609
                    Système de fichiers : NTFS

                    Executé en mode sans échec

                    *** Recherche Programmes installés ***

                    *** Recherche dossiers dans C:\Windows ***

                    *** Recherche dossiers dans C:\Program Files ***

                    *** Recherche dossiers dans C:\ProgramData ***

                    *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

                    *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs ***

                    *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Local\virtualstore\Program Files ***

                    *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Roaming ***

                    *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                    pour + d'infos : http://www.gmer.net

                    Aucun Fichier trouvé

                    *** Recherche avec GenericNaviSearch ***
                    !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                    !!! A vérifier impérativement avant toute suppression manuelle !!!

                    * Recherche dans C:\Windows\system32 *

                    * Recherche dans C:\Users\Lexxcoop\AppData\Local\Microsoft *

                    * Recherche dans C:\Users\Lexxcoop\AppData\Local\virtualstore\windows\system32 *

                    * Recherche dans C:\Users\Lexxcoop\AppData\Local *

                    *** Recherche fichiers ***

                    *** Recherche clés spécifiques dans le Registre ***

                    *** Module de Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Recherche nouveaux fichiers Instant Access :

                    2)Recherche Heuristique :

                    * Dans C:\Windows\system32 :

                    * Dans C:\Users\Lexxcoop\AppData\Local\Microsoft :

                    * Dans C:\Users\Lexxcoop\AppData\Local\virtualstore\windows\system32 :

                    * Dans C:\Users\Lexxcoop\AppData\Local :

                    3)Recherche Certificats :

                    Certificat Egroup absent !

                    4)Recherche fichiers connus :

                    *** Analyse terminée le 2008-02-26 à 23:48:23.32 ***

                    Log Navilog

                    Ici Le HJT

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 23:49, on 2008-02-26
                    Platform: Windows Vista (WinNT 6.00.1904)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                    Boot mode: Safe mode with network support

                    Running processes:
                    C:\Windows\Explorer.EXE
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Windows\system32\wbem\unsecapp.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Windows\notepad.exe
                    C:\Windows\system32\NOTEPAD.EXE
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fnhotmail%2fhelp%2f%3f
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                    O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'SYSTEM')
                    O4 - HKUS\S-1-5-18\..\Run: [NoDNS] C:\Program Files\\NoDNS\\NoDNS.exe (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'Default user')
                    O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O13 - Gopher Prefix:
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                    O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
                    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                    O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
                    O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                    O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
                    O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
                    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                    0
                    1. Search Navipromo version 3.4.2 commencé le 2008-02-26 à 23:34:38.55

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!
                      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                      Outil exécuté depuis C:\Program Files\navilog1
                      Mise à jour le 21.01.2008 à 14h00 par IL-MAFIOSO

                      Microsoft Windows Vista 6.0.6000
                      Internet Explorer : 7.0.6000.16609
                      Système de fichiers : NTFS

                      Executé en mode sans échec

                      *** Recherche Programmes installés ***

                      *** Recherche dossiers dans C:\Windows ***

                      *** Recherche dossiers dans C:\Program Files ***

                      *** Recherche dossiers dans C:\ProgramData ***

                      *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

                      *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs ***

                      *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Local\virtualstore\Program Files ***

                      *** Recherche dossiers dans C:\Users\Lexxcoop\AppData\Roaming ***

                      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                      pour + d'infos : http://www.gmer.net

                      Aucun Fichier trouvé

                      *** Recherche avec GenericNaviSearch ***
                      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                      !!! A vérifier impérativement avant toute suppression manuelle !!!

                      * Recherche dans C:\Windows\system32 *

                      * Recherche dans C:\Users\Lexxcoop\AppData\Local\Microsoft *

                      * Recherche dans C:\Users\Lexxcoop\AppData\Local\virtualstore\windows\system32 *

                      * Recherche dans C:\Users\Lexxcoop\AppData\Local *

                      *** Recherche fichiers ***

                      *** Recherche clés spécifiques dans le Registre ***

                      *** Module de Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Recherche nouveaux fichiers Instant Access :

                      2)Recherche Heuristique :

                      * Dans C:\Windows\system32 :

                      * Dans C:\Users\Lexxcoop\AppData\Local\Microsoft :

                      * Dans C:\Users\Lexxcoop\AppData\Local\virtualstore\windows\system32 :

                      * Dans C:\Users\Lexxcoop\AppData\Local :

                      3)Recherche Certificats :

                      Certificat Egroup absent !

                      4)Recherche fichiers connus :

                      *** Analyse terminée le 2008-02-26 à 23:48:23.32 ***

                      Log Navilog

                      Ici Le HJT

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 23:49, on 2008-02-26
                      Platform: Windows Vista (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                      Boot mode: Safe mode with network support

                      Running processes:
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Windows\notepad.exe
                      C:\Windows\system32\NOTEPAD.EXE
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fnhotmail%2fhelp%2f%3f
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                      O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\Run: [NoDNS] C:\Program Files\\NoDNS\\NoDNS.exe (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'Default user')
                      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                      O13 - Gopher Prefix:
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                      O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                      O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
                      O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                      O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
                      O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
                      O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                      0
                      1. Re

                        Utilise tu un antivirus ?

                        Fixe les lignes dans Hijackthis :

                        Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

                        S'il te demande un redémarrage, relance ton PC.
                        _____________________________________________________

                        Relance OTMoveIt :

                        = Copier le texte en gras:

                        C:\Windows\system32\wininit.exe

                        = Double-clic sur OTMoveIt.exe
                        = Dans le cadre de Gauche ==> clic-droit ==> coller
                        = Clic MoveIt!
                        = si redémarrage demandé==> Clic : YES
                        = Un rapport dans ==> C:\_OTMoveIt\MovedFiles\date du jour à copier/coller sur le forum.
                        -------

                        redemarre le PC

                        _____________________________________________________

                        - Télécharger et installer AVG Anti-Spyware 7.5 (si tu ne l'as pas déjà et si tu l'as, vérifie bien les paramètres "rapports").

                        https://www.avg.com/en-ww/free-antivirus-download

                        Lancer AVG Anti-Spyware.
                        Cliquer sur le menu Mise à jour.
                        Dans le paragraphe "Mise à jour manuelle", cliquer sur le bouton "Commencer la mise à jour".
                        Attendre la fin de cette mise à jour puis fermer le programme.

                        - Lance AVG Anti-Spyware 7.5

                        Cliquer sur le menu" Analyse" (de la barre d'outils).
                        Cliquer sur l'onglet "Paramètres".
                        Dans "Comment réagir"? cliquer sur "Actions recommandées" et choisir "Quarantaine".
                        Dans Comment faire l'analyse ? et dans Programmes potentiellement dangereux, vérifier que toutes les cases soient cochées.
                        Dans "Rapports" vérifier que la case "Générer un rapport après chaque analyse" soit aussi coché.
                        Dans l'onglet "Analyse"
                        Cliquer sur "Analyse complète du système".
                        Important : Ne pas ouvrir de fenêtre, ne pas lancer de programme pendant l'exécution de AVG Anti-Spyware, car cela pourrait interférer avec le processus de recherche.
                        Très important : A la fin de l'analyse, cocher tout ce qui a été trouvé puis cliquer sur " Appliquer toutes les actions"
                        Ensuite.
                        Cliquer sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
                        (C:\Programfiles\Grisoft\AVG Antispyware 7.5\Reports )
                        Puis fermer AVG Anti-Spyware.

                        _____________________________________________________

                        Pour les Antispy, je te conseil en premier cas :

                        Spybot 1.5 :
                        https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

                        Attention de ne pas cocher "teaTimer" lors de l'installation.

                        puis aprés,

                        Ad-Aware :
                        http://www.commentcamarche.net/telecharger/telecharger 83 ad aware 2007 free

                        (l'un, l'autre, ou les deux)

                        _____________________________________________________

                        Télécharger et installer CCleaner.

                        https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

                        Clique sur Options, Avancé et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
                        Ne touche pas aux autres réglages.
                        Lancer un nettoyage et répare 3 fois les erreurs
                        sans installer la barre yahoo.

                        Aprés, va dans l'onglet Registre puis cherche les erreurs
                        une fois terminé, Répare les erreurs selectionnées

                        _____________________________________________________

                        Aprés tous ça, Ton PC sera a nouveau opérationnel

                        :)
                        0
                        1. Move it n app pas reussi a enlever un fichier !
                          Je n utilise pas dantivirus .. sur xp j utilisais avast !

                          File move failed. C:\Windows\system32\wininit.exe scheduled to be moved on reboot.

                          OTMoveIt2 v1.0.20 log created on 02272008_002429

                          Scan avg a plante je recommence et le poste ensuite
                          0
                          1. avg rapport

                            C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NHC656LU\8154ff2675af1b6e0677560871425153[1].zip/b138.exe -> Downloader.Agent.cbx : Nettoyé et sauvegardé (mise en quarantaine).
                            C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFWUDU6F\f4d28682d186cc6beb75f106d133f489[1].zip/b128.exe -> Downloader.Agent.ezc : Nettoyé et sauvegardé (mise en quarantaine).
                            C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFWUDU6F\4e51764f761ae09c14e873232d26919b[1].zip/b111.exe -> Downloader.Agent.fjv : Nettoyé et sauvegardé (mise en quarantaine).
                            C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
                            C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@sevenloadgmbh.112.2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
                            :mozilla.76:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
                            :mozilla.77:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
                            C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@advertising[1].txt -> TrackingCookie.Advertising : Nettoyé.
                            :mozilla.78:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
                            C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyé.
                            :mozilla.69:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
                            :mozilla.70:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
                            C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
                            :mozilla.53:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Revsci : Nettoyé.
                            :mozilla.89:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
                            C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
                            C:\Users\Lexxcoop\AppData\Roaming\Microsoft\Windows\Cookies\lexxcoop@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Nettoyé.
                            :mozilla.20:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                            :mozilla.21:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                            :mozilla.22:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                            :mozilla.23:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                            :mozilla.24:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
                            :mozilla.25:C:\Users\Lexxcoop\AppData\Roaming\Mozilla\Firefox\Profiles\upusp6k3.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.

                            Fin du rapport

                            nettoyage c cleaner effectué aussi !
                            0
                            1. Salut,

                              Si si, il a était supprimé par OTMoveIt.

                              Refait moi un log HijackThis please merci.

                              ++
                              0
                              1. Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 16:53, on 2008-02-27
                                Platform: Windows Vista (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                                C:\Windows\system32\conime.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Windows\System32\mobsync.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fnhotmail%2fhelp%2f%3f
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
                                O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [MapEDC] C:\Program Files\MapEDC\MapEDC.exe (User 'Default user')
                                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                O13 - Gopher Prefix:
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                                O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                                O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                                O23 - Service: MySql - Unknown owner - C:\mysql\bin\mysqld-nt.exe
                                O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                O23 - Service: Transcoding and Broadcast Service (Transcode360) - Unknown owner - C:\Program Files\Transcode360\Transcode360.exe
                                O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
                                O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.6\bin\httpd.exe
                                O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.45\bin\mysqld-nt.exe
                                O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                                0
                                1. Salut

                                  Je te conseil fortement cependant d'utiliser un antivirus,
                                  Tu as Antivir éfficace et gratuit :

                                  Pour installer Antivir :

                                  Telecharge Antivir: http://www.commentcamarche.net/telecharger/telecharger 55 antivir

                                  Installe le.
                                  Pendant l'installation, cocher la case "generate random serial..."
                                  Lance Antivir,
                                  fais les mises à jours
                                  Relance ton PC

                                  Tutos : https://www.malekal.com/avira-free-security-antivirus-gratuit/

                                  Si problème - mise à jour :
                                  Telecharge la licence sur le site officiel :
                                  http://dl1.avgate.net/down/windows/hbedv.key
                                  Une fois telechargé, déplace le fichier téléchargé (hbedv.key) dans le dossier Antivir.
                                  Par defaut : C:\Program Files\AntiVir PersonalEdition Classic

                                  Refait la mise à jour, puis il ne sera plus périmé.

                                  _____________________________________________________

                                  Fixe les lignes dans Hijackthis :

                                  Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

                                  S'il te demande un redémarrage, relance ton PC.
                                  _____________________________________________________

                                  Comment se comporte ton PC ?
                                  Encore des fenetre qui s'ouvrent ?
                                  0
                                  1. Non en fait depuis hier soir plus aucune fenetres ou de problemes avec msn !
                                    ligne fixéé sur Hjt !!!
                                    n grand merci pour l'assistance!
                                    0
                                    1. on se demande à quoi sert windows defender...!
                                      0
                                  2. Pas de problème,

                                    On va terminer avec ça :

                                    Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.

                                    * http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe

                                    * Clique sur Recherche et laisse le scan se terminer.
                                    * Clique, sur Suppression pour finaliser.
                                    * Tu peux, si tu le souhaites, te servir des Options facultatives.
                                    * Clique sur Quitter, pour que le rapport puisse se créer.
                                    * Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
                                    ---------------------------------------------

                                    Tu peux le supprimer une fois le rapport sur le forum.
                                    _____________________________________________________

                                    Maintenant que ton PC n'est plus infecté, désactive ta "Restauration du système" puis réactive la afin de créer un point de restauration sain.

                                    * Désactivation :
                                    Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
                                    > Appliquer patiente jusqu a que cela soit marqué "désactivée" puis Ok.

                                    * Activation :
                                    Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
                                    > Appliquer attends que cela soit a nouveau sur "surveillance" puis Ok. Redémarrer l'ordinateur...
                                    0
                                    1. Windows Defender te sers de par feu, Celui de vista et suffisent.
                                      Mais tu n'as pas d'antivirus la par contre c'est moin bien, je te conseil quand même d'installer Antivir :)
                                      0
                                      • 1
                                      • 2